Attachment 9- SST PM Support PWS.pdf
PDF 398 KB Posted
- Attached to
- Specialized Security Training Federal contract opportunity
- Solicitation number
- 70T01021R7670N004
About this file
This performance work statement outlines program management support services required by the Transportation Security Administration's Office of Training & Development. Key details include:
-
The contractor shall provide centralized program management oversight and support for all task orders issued against the Specialized Security Training 4.0 IDIQ, including scheduling, finance, milestones, deliverables, and overall program performance.
-
The contractor's program manager will act as the central point of contact and represent the contractor at all post-award meetings.
-
The contractor must develop an integrated master schedule in Microsoft Project to track progress across task orders and provide schedules and status reports to the COR on a weekly, monthly, and quarterly basis.
-
The base period of performance is one year with four additional one-year option periods. Work will be performed at the contractor's facilities but meetings may occur at TSA headquarters.
-
The contractor shall comply with all applicable TSA, DHS, and federal security, accessibility, records management, and reporting requirements.
View the file
Other files for this federal contract opportunity
Show all 26
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement (PWS)
1 Requiring Organization
The Government organization requiring the services described herein is as follows:
Department of Homeland Security Transportation Security Administration Training and Development 601 South 12th Street, 3rd Floor, East Building Arlington, VA 20598
*Note: TSA headquarters is scheduled to relocate to Springfield, VA in Fall 2020.
2 Background
The Aviation and Transportation Security Act (ATSA), Public Law 107-71, requires the TSA to develop, implement, and manage training programs for the transportation security workforce. In compliance with ATSA, the Office of Training & Development (T&D) is responsible for the analysis, design, development, implementation and evaluation of training programs for employees, the transportation industry, and international partners. The focus of all training is to support and increase the TSA workforce technical expertise, professionalism, and engagement effectiveness. TSA’s Risk-Based Security environment must evolve to meet rapidly changing threats. TSA must be prepared to address and meet the demands of an increasingly complex operation within tight timelines and budgetary constraints.
P.L. 107-71 also mandates that Transportation Security Officers (TSO) employed as security screeners may not use any screening device or equipment in the scope of their employment unless they have been trained on that device or equipment and have successfully passed all required assessments for certification or recertification. Additionally, TSOs must be proficient in using the most up-to-date technology in recognizing new threats and weapons, including dual-use items that appear harmless but may be used as weapons.
3 Scope of Work
TSA Training & Development (T&D) requires centralized program management support services to provide seamless program oversight for all T&D task orders issued against the SST 4.0 Indefinite Delivery Indefinite Quantity (IDIQ).
The Contractor shall provide comprehensive program management oversight to ensure efficiencies and integration across all T&D task orders to include such tasks as scheduling, finance, milestones, deliverables, and overall program performance in accordance with the IDIQ Performance Work Statement (PWS) and this Task Order.
4 Key Personnel
4.1 Task Order Program Manager (Key Personnel)
http://www.gpo.gov/fdsys/pkg/PLAW-107publ71/pdf/PLAW-107publ71.pdf
4.1.1 The Contractor’s Program Manager is designated as key personnel, and shall act as the central point of contact with the Government for all technical and management issues, and will represent the Contractor at all Task Order-level post-award status meetings. The Program Manager shall be responsible for all Task Order-level issue resolution, program management, and other contract support including providing comprehensive account support for the SST contract. The Program Manager is responsible for overall PM Support Task Order performance.
5 Place of Performance
Contractor employees will work at the Contractor’s facilities. The contractor’s Program Management Team shall be available to meet at TSA Headquarters in Springfield, VA, as required by TSA.
6 Period of Performance
One (1) 12-month base period.
Four (4) 12-month option periods
7 Program Management
7.1 The Contractor shall provide Program Management oversight of all work performed under all T&D
Task Orders to include schedule, milestones, cost, finance, products, deliverables and overall program performance as described in the IDIQ PWS and this Task Order.
7.2 The Contractor shall utilize the TSA system of record and/or the TSA iShare Project Site(s) to update status on overall task management activities, initiate and track Requests for Quotation (RFQs), WebForms, Program Project/Task/sub-task level reporting and data management.
7.3 Integrated Master Schedule
7.3.1 The Contractor shall develop and maintain an Integrated Master Schedule (IMS) in Microsoft
Project to track and report progress for each project across all T&D task orders.
7.3.2 The Contractor shall provide a comprehensive and individual project schedules, which identify efforts that may be performed by partnering Contractors supporting other SST task orders, to the COR with the submission of the MTSR.
7.3.3 Any significant change equaling an increase of 10% to the approved schedule shall require a re-baselined project schedule.
7.4 The Contractor shall provide a summary of meetings with TSA, to include a list of all action items, to the COR no later than (NLT) COB three (3) Business Days following each meeting.
7.5 The Contractor shall conduct one (1) Program Management Review (PMR) per quarter to outline the previous quarter’s activities, issues, and risks in addition to a forecast on all projects across T&D task orders, on a task by task basis, with associated CLINs.
7.5.1 In order to assume cost savings, the Government may use a teleconference and the Contractor is required to possess teleconferencing capability.
7.5.2 Softcopy slides (via e-mail) shall be provided to the COR 72 hours prior to the PMR.
7.6 Post-Award Conference
7.6.1 The Post-Award conference will cover the terms and conditions of the task order, contract administration, and other administrative concerns.
7.6.2 The Post-Award Conference is to be held no later than two (2) weeks (10 business days), after the date of Task Order award. The Contractor will be contacted by the Contract Specialist or the COR to coordinate the Post-Award Conference. Post-Award Conference may be held virtually as directed by the Government.
8 Reporting Requirements
8.1 Unless otherwise specified, the Contractor shall submit deliverables in the format specified in the task order specific deliverable tables. Electronic copies of deliverables must have read/write capability unless otherwise requested. For resultant deliverables that are not identified in the deliverable schedule, the Contractor shall submit an electronic copy of the deliverable in a format agreed upon by both parties. Electronic copies shall be delivered via TSA’s designated system of record, or otherwise as directed by TSA. The electronic copy shall be compatible with TSA computer workstations, requiring, at a minimum, Adobe PDF and Microsoft Office 2010 format application or a format for digital storage mutually agreed to by the parties. The Contractor shall successfully complete and submit products in accordance with the requirements of each task. All source files including individual components such as images, and videos shall be submitted with each deliverable.
8.2 The Contractor shall develop and maintain program schedules and track/report progress for each separate task performed under all T&D task orders. This shall include a combined Weekly Status Report (WSR) due by COB Monday of every week.
8.2.1 The Weekly Status Report shall detail the previous week’s activity and contain the following:
8.2.1.1 Current project schedule for each task
8.2.1.2 Weekly Progress (task specific)
8.2.1.3 Weekly Projected Activity (task specific)
8.2.1.4 Click Count for the week, month, and from inception
8.2.1.5 Risk Reporting – Communication of any risks to TSA operations
8.2.1.6 Instructor Certification/Recertification – Dates and status of instructor certifications, expiration dates, and recertification plans
8.2.1.7 Instructor Utilization – A summary of instructor utilization by training program, including current and planned instructor deployments
8.2.1.8 Logistics Activity – By program, the Contractor shall report on logistics activity to include an Instructor Deployment Summary and Class Deliveries
8.2.1.9 Task Specific Travel – The Contractor shall include weekly travel reporting that addresses all planned, forecasted, and completed travel. Forecasted travel shall identify planned travel 30 days prior to travel dates in order to allow for Government approval
8.2.1.10 Schedule Reporting – The Contractor will report progress for each separate project conducted under T&D task orders, identifying scheduled start and end dates, schedule risks and vulnerabilities, status of project milestones, required response timeframes from TSA and general project status
8.2.1.11 Quality Trend Report – This report shall only be included if the contractor has evaluation information to report. Otherwise, it should not be included in the weekly report. As part of the Kirkpatrick Levels of Evaluation, TSA expects the Contractor to provide this report along with the other evaluation documents listed in T&D Curriculum PWS task order.
8.2.1.12 Naming Convention: The WSR shall be titled using the below naming convention.
• Contract_Last_Six-Deliverable_Name-YYYYMMDD
• Example: OTD101-WSR-20200812
8.2.2 The Contractor shall provide a Monthly Financial Summary Report (MFSR) detailing all financial information due fifteen (15) calendar days after month end, or the first business day thereafter, and contain the following:
8.2.2.1 The MFSR shall include a section to identify contract information, including:
• Contract number, Task Order Numbers, and modification number(s), if any;
• Reporting period (Month);
• Contract period (Base / Option #);
• Contract period of performance start and end date.
8.2.3 The MFSR shall detail all financial information contract-wide and on each T&M project, by invoiced month, as follows:
8.2.3.1 The MFSR shall include a section reflecting actual monthly and cumulative (by total contract and contract period) expenditures, staffing utilization (labor hours and cost), ODCs, and travel services for the reporting period.
8.2.3.2 A breakout of funds expended on RFQs/Technical Directions (TD) (T&M work) shall be included in this information including cumulative total funds provided to date and a detail of actual monthly/cumulative expenditures and funds remaining to date, inclusive of current period charges.
8.2.3.3 The Contractor shall detail the cost of expenditures per RFQ/TD, on a per project per task basis, reflecting current and cumulative labor hour costs, ODCs and travel expended.
8.2.3.4 When a project/task is submitted, the Contractor shall provide an initial cost estimate of expenditures at completion (EAC).
8.2.3.5 The Contractor shall also tag the projects by status: ongoing, on hold, terminated, and complete;
8.2.3.6 The MFSR shall include a variance (%) comparison of planned costs to actuals including labor category costs, a current Estimate at Completion (EAC), funds remaining, and actual cumulative expenditures, per project and rolled up to the TO level;
8.2.3.7 Additional financial data shall be provided to the Government upon request.
8.2.3.8 Naming Convention: The MFSR shall be titled using the below naming convention.
• Contract_Last_Six-Deliverable_Name-Month_Covered-YYYYMMDD
• Example: OTD101-MFSR-07-20200812
8.2.4 Monthly Technical Summary Report (MTSR)
8.2.4.1 This deliverable shall be submitted fifteen (15) calendar days after month end, or the first business day thereafter.
8.2.5 The MTSR shall summarize work accomplished (to align with activity-based cost reporting) during the reporting period. It shall reflect the status of technical services on each task, to include the following:
8.2.5.1 Deliverables submitted or progress achieved on deliverables;
8.2.5.2 A brief summary of status and completion of significant events and milestones and activity planned for the next reporting period; current and anticipated issues, estimate of schedule impacts due to issues (to include a Schedule Performance Index (SPI).
8.2.5.3 Other relevant information, as necessary to convey program status; quality assurance; and/or quality control information.
8.2.5.4 ODCs and Travel Report
8.2.5.4.1 The Contractor shall be required to support consolidated labor hour, travel, and cost reporting for each T&M effort.
8.2.5.4.2 For each Contractor/subcontract employee, identify the name, labor category/skill level, regular and overtime hours worked per WBS element for each T&M effort.
8.2.5.5 ODC Forecast
8.2.5.5.1 Description of any travel or unique services anticipated to be provided within the next month.
8.2.5.5.2 Description of any other anticipated ODCs within the next month.
8.2.5.6 Naming Convention: The MTSR shall be titled using the below naming convention.
• Contract_Last_Six-Deliverable_Name-Month_Covered-YYYYMMDD
• Example: OTD101-MTSR-07-20200812
8.2.5.7 Monthly Property Inventory Reports
8.2.5.8 The Contractor shall provide TSA with a monthly report as an attachment to the Monthly
Technical Status Report submission due on the same date as monthly invoice submission, which includes an inventory list of all assets and a reconciliation of inventory across all Government and Contractor property management systems. Government assessments, reviews, audits, and operations in general, may include physical inventory, document analysis, observations, physical examination, confirmation, interviews, questionnaires, and/or other assessment to obtain an opinion on the effectiveness of controls, accuracy of inventory, and test of design for process efficiency and effectiveness.
9 Quality Assurance
9.1 Quality Assurance
9.1.1 The Contractor shall ensure that all T&D task order performance objectives and deliverables are of the highest achievable quality; promote continuous improvement efforts; and ensure industry/enterprise practices are employed at all times. Contractor processes and Standard Operating Procedures (SOPs) shall be followed and are auditable by TSA.
9.1.1.1 The Contractor shall propose a Quality Control Plan for each task listed in the T&D Threat
Mitigation, Engineering, and Imaging (TME&I) and Curriculum task orders. The due date will be agreed upon by the Government and Contractor.
9.1.2 The format and content of deliverables shall be agreed upon, in advance, between the COR and
Contractor for T&M work task items. Inspection and acceptance of all deliverables required under this PWS will be performed by the COR. All deliverables are due by 12:00 pm ET on the day specified, unless otherwise stated. If the Government finds that deliverables contain errors, or otherwise do not conform to the requirements stated within this TO, the document will be returned to the Contractor, as soon as the error or other non-conformance becomes known, for correction and re-submission within three (3) business days. Detailed technical records and/or notes should be available to the COR for review of any requirement at any time during the period of performance, and all research material compiled as part of this TO shall be provided to the Government upon completion of each period of performance. The date, time, method, and location for meetings is to be agreed upon between the Government COR and the Contractor.
9.1.3 The COR will coordinate the Quality Assurance activities, to include the Quality Assurance Team
(Program Manager, Accountable Property Officer, Property Custodian, and Project Lead) when required.
9.1.4 The below listed methods may be used to conduct Quality Assurance.
9.1.4.1 Deliverable Review – A review of the deliverables will be conducted based on the following criteria: Delivery, Technical, Content, Management, and Cost Performance.
9.1.4.2 100% Inspection – This level of inspection will be accomplished as designated by TSA. The 100% inspection of GFE/GFP may be broken down into percentages for ease of scheduling and to minimize the impact on operations. The percent should equal 100% for the period designated (i.e. Period of Performance, annual).
9.1.4.3 Periodic Inspection – Periodic inspections will be scheduled by the COR if and when needed.
Personnel performing the random inspection shall be designated by the COR. The COR, with the Quality Assurance Team when required, will determine the timing of the inspection and the area(s) of Contractor performance to be inspected.
9.1.4.4 Random Inspection – Random monitoring will be directed by the COR if and when required.
Personnel performing the random inspection shall be designated by the COR, to include the Quality Assurance Team as required.
9.1.4.5 Customer Feedback – Feedback may be obtained either from the results of formal deliverable review or from informal customer statements to ensure that the Contractor has satisfactorily completed tasks as required. Customer feedback shall be solicited by TSA personnel, normally the Project Lead, and reported to the COR. All unsatisfactory reports will be reviewed by the Project Lead for validity for reporting to the COR.
9.1.5 Quality Planning – The Contractor shall conduct a complete review of the detailed requirements to identify all test and inspection resources are necessary for assuring product integrity.
9.1.6 Document Control – The Contractor shall ensure that the latest revisions of drawings, specifications, work instructions, inspection/test instructions, and other documents required to satisfy the requirements herein are utilized in production, inspection, and test.
9.1.7 Records – The Contractor shall maintain records of all inspections and tests to demonstrate that each quality approach satisfies contract requirements.
9.1.8 Control of Purchases – The Contractor shall ensure that all supplies and services which are contracted and/or purchased from suppliers conform to contract requirements. The Contractor shall require that sub-contractors control the quality for services and supplies provided.
9.1.9 General Acceptance Criteria – General quality measures as set forth below shall be applied to each work product received from the Contractor under this contract.
9.1.9.1 Accuracy – Work products shall be accurate in presentation, technical content, and adherence to accepted elements of style.
9.1.9.2 Clarity – Work products shall be clear and concise. Any/all diagrams shall be easy to understand and be relevant to the supporting narrative.
9.1.9.3 Consistency to Requirements – All work products must satisfy the requirements of this PWS.
9.1.9.4 File Editing – All text and diagrammatic files shall be editable by the Government, unless otherwise directed.
9.1.9.5 Format – Work products shall be submitted in media mutually agreed upon prior to submission.
Hard copy formats shall follow any specified directives or manuals.
9.2 Section 508 of the Rehabilitation Act
9.2.1 See the SST Base IDIQ.
9.3 Non-Disclosure Agreements
9.3.1 Contractor employees, prior to beginning work, shall sign a non-disclosure agreement to be furnished to the CO.
9.4 DHS and TSA Security Requirements
9.4.1 SST Base ID/IQ section C.7.
9.5 Sensitive Security Information (SSI), Personally Identifiable Information (PII), and Incident
Response
9.5.1 Contractor access to classified information is not currently required under this effort. However, during performance, it may be necessary for the Contractor to handle sensitive or proprietary information pertinent to TSA’s operations, which must be handled in accordance with TSA’s applicable policies and procedures. Please reference the Base Indefinite Delivery, Indefinite Quantity (IDIQ) Section C.7.1 and C.7.2. (DHS and TSA Enterprise Architecture Compliance), H.23 5200.224.002 Controlled Unclassified Information Data Privacy and Protection, TSA Management Directive 2810, and H.30 2500.224.001 Security of Systems Handling Personally Identifiable Information and Privacy Incident Response.
9.6 Government Service Location Requirements
9.6.1 This effort requires the Contractor to perform at various TSA sites. While Contractor personnel are at the Government site, they shall comply with all rules and regulations in effect at that site.
9.6.2 The Contractor shall not connect its privately-owned portable computers to the TSA local area network, nor may it use TSA’s voice over internet protocol telephone system to connect its portable computers to its home office(s).
9.7 Compliance with Service Contract Labor Standards
9.7.1 This task order is subject to the provisions of 41 U.S.C. chapter 67, Service Contract Labor
Standards (formerly known as the Service Contract Act of 1965). Compliance with the applicable Department of Labor’s Wage Determinations is required.
9.8 Intellectual Property
9.8.1 Intellectual property shall be handled in accordance with the relevant clauses in the Base SST IDIQ contract, including FAR clauses 52.227-3, 52.227-11, 52.227-14, 52.227-16, and 52.227-17. As such, all associated documentation, including reports, curriculum, etc., created by the Contractor under this task order shall become the property of the TSA. No proprietary markings shall be on any deliverables submitted to TSA.
9.9 Government Furnished Information (GFI)
Government Furnished Information shall be handled in accordance with the following:
• Aviation and Transportation Security Act, P.L. 107-71, 49 U.S.C. 44940 https://www.gpo.gov/fdsys/pkg/PLAW-107publ71/content-detail.html
• Transportation Security Administration Management Directive No. 3100.1
10 Contractor Personnel Requirements
10.1 All labor proposed for the requirements defined herein shall meet the labor qualifications described in Attachment 2 to the Specialized Security Training (SST) base IDIQ contract, which is entitled “B.2 – Labor Category List and Qualifications”. The Government may request the résumé of any support personnel to verify that personnel meet the qualified personnel requirements described herein. The Contractor shall provide qualified personnel in sufficient numbers to meet the requirements of this Performance Work Statement (PWS). Personnel must be adequately trained to perform the functions necessary to meet the requirements of this PWS.
10.2 Program Manager (PM)
10.2.1 The Contractor shall provide a Program Manager(s) who shall be responsible for all Contractor work performed under this PWS.
10.2.2 The Program Manager shall be a single point of contact for the Contracting Officer (CO) and the
Contracting Officer’s Representative (COR). It is anticipated that the PM shall be one of the senior level employees provided by the Contractor for work performed under this PWS. The name of the PM, and the name(s) of any alternate(s) who shall act for the Contractor in the absence of the PM, shall be provided to the Government as part of the Contractor's proposal.
10.2.3 During any absence of the PM, the designated alternate(s) shall have full authority to act for the
Contractor on all oversight matters relating to work performed under this PWS.
10.2.4 The Contractor shall not replace the PM without prior acknowledgement from the CO.
10.2.5 The PM shall be available to the COR via telephone between the hours of 0800 and 1700 EST
Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within 2 hours of notification.
11 Transition-In
The contractor shall provide transition-in services that ensure all Contractor personnel are ready to assume work in progress from the outgoing Contractor and assume new work at the start of the task order. Two (2) months are allotted for this task, which shall include processing of clearances, shadowing of the outgoing Contractor, and other required services.
https://www.gpo.gov/fdsys/pkg/PLAW-107publ71/content-detail.html
12 Transition Out
12.1 The Contractor shall develop a Transition Out Plan that describes a transition out strategy, and identifies transition data and information, systems, components, documentation, functionality, services, service dependencies, services interfaces, risks, transition work activities, schedule, staffing down approach, knowledge transfer, and any other information that needs to be considered to ensure a smooth transition.
12.2 The Contractor shall deliver the Transition Out Plan to the COR within nine (9) business days from the TSA request. Upon acceptance by TSA, the Contractor shall execute the Transition Out Plan and complete within the period of performance designated for the applicable CLIN.
12.3 The Contractor shall provide an inventory of all operational, procedural, educational, and any other documentation and presentations produced as part of delivering upon the TSA request.
12.4 The Contractor shall continue to fulfill the current contractual requirement(s) and continue all current work in progress until the successor contractor assumes full operational responsibility as determined by TSA. The Contractor shall not destroy, delete, or otherwise dispose of any files or data upon expiration or termination of the [contract/order], without prior permission from the
COTR.
12.5 The Contractor shall fully cooperate with the successor contractor and the Government during transition out so as not to interfere with their work or duties.
12.6 The Contractor shall fully support all TSA requests for information and data required to ensure a seamless transition of services to a new contractor.
12.7 The Contractor shall deliver to the TSA electronic copies of all TSA data and information developed for TSA in the format requested by TSA within 30 calendar days from the TSA request, including print-ready files and original modifiable source files for all current courses in the National Training Plan and the Course Catalogue. Any new files developed after the Contractor’s submission shall also be sent to TSA. This shall include but is not limited to the following:
12.7.1 The final version of all courseware, job aids, guides, etc. This includes Learning Management
System (LMS) and Computer Based Training (CBT) versions of Interactive Multimedia Instruction (IMIs), instructor guides, participant guides, PowerPoint presentations, test maps, etc.;
12.7.2 All source files for the final products, in an editable format and including components such as images, videos, and any other multimedia;
12.7.3 All Government Furnished Information (GFI) tied to each product;
12.7.4 All Training Curriculum Updates (TCUs);
12.7.5 An index of everything that the contractor provides that includes the file name, file type, and location;
12.7.6 The files shall be delivered electronically, via a TSA-approved, encrypted external hard drive to the TSA Contracting Officer or their designee;
12.7.7 At the conclusion of the contract, the contractor shall transition information collected or used during the performance period including computer files and databases in Microsoft and Adobe applications.
13 Deliverable Table
Section Deliverable Submission Method Due Date Recipient
6.3.2 Integrated Master
Schedule (IMS) Email to COR As an attachment to
MTSR submission COR
6.4 Meeting Minutes Email to COR 3 business days COR
6.5 Program
Management Review
Email to COR Quarterly, as agreed upon by TSA and the
Contractor
COR
6.6.2 Post-Award
Conference
In person or virtual, as directed by TSA
Within 10 business days of award COR, PM
7.2 Weekly Status
Report (WSR) Email to COR COB Every Monday COR
7.2.2 Monthly Status Financial Report
(MFSR)
Email to COR
Fifteen (15) calendar days after month end, or the first business day thereafter
COR
7.2.4 Monthly Technical Summary Report
(MTSR)
Email to COR
Fifteen (15) calendar days after month end, or the first business day thereafter
COR
7.2.5.8 Monthly Property
Inventory Report Email to COR As an attachment to the MTSR submission COR
8.1.1.1 Quality Control
Plan Email to COR
As agreed upon by TSA and the Contractor
COR
11.2 Transition Out Plan Email to COR Within 9 business
days of TSA request COR
11.7 All TSA Data
Upload to TSA system of record, Email, CDs or other as specified
Within 30 days of TSA Request COR
13.1 Review and acceptance will be conducted in accordance with the SST Base ID/IQ.
13.2 The COR will review deliverables prior to acceptance and provide the Contractor with email notification of acceptance or rejection.
14 Appendix D - Information Assurance Requirements for TSA Government Acquisitions (April 2016)
A. General Security Requirements
A.1. The Contractor shall comply with all Federal, Department of Homeland Security (DHS) and Transportation Security Administration (TSA) security and privacy guidelines in effect at the time of the award of the contract, as well as those requirements that may be discretely added during the contract.
A.2. The Contractor shall perform periodic reviews to ensure compliance with all information security and privacy requirements.
A.3. The Contractor shall comply with all DHS and TSA security controls to ensure that the Government's security requirements are met. These controls are described in DHS PD 4300A and TSA MD 1400 series security policy documents and are based on the current National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 standards.
A.4. The Contractor shall include this guidance in all subcontracts at any tier where the subcontractor is performing the work defined in this statement of work (SOW).
A.5. The Contractor shall ensure all staff have the required level of security clearance commensurate with the sensitivity of the information being accessed, stored, processed, transmitted or otherwise handled by the System or required to perform the work stipulated by the contract. At a minimum, all Contractor staff shall be subjected to a Public Trust background check and be granted a Public Trust clearance before access to the System or other TSA resources is granted.
A.6. The Contractor shall sign a DHS Non-Disclosure Agreement (NDA) within (30) calendar days of the contract start date.
A.7. The Contractor shall not release, publish, or disclose agency information to unauthorized personnel, and shall protect such information in accordance with the provisions of the pertinent laws and regulations governing the confidentiality of sensitive information.
A.8. The Contractor shall ensure that its staff follow all policies and procedures governing physical, environmental, and information security described in the various TSA regulations pertaining thereto, and the specifications, directives, and manuals for conducting work to generate the products as required by this contract. Personnel shall be responsible for the physical security of their area and government furnished equipment (GFE) issued to the contractor under the terms of the contract.
A.9. The Contractor shall make all system information and documentation produced in support of the contract available to TSA upon request.
B. Training Requirements
B.1. All Contractor employees, requiring system access, shall receive initial Organizational Security Fundamentals Training within 60 days of assignment to the contract via the Online Learning Center (OLC). Refresher training shall be completed annually thereafter.
B.2. The Contractor shall complete annual online training for Organizational Security Fundamentals https://team.ishare.tsa.dhs.gov/sites/OTWE3/OLC/OLC%20Home%20Page.aspx https://team.ishare.tsa.dhs.gov/sites/OTWE3/OLC/OLC%20Home%20Page.aspx and TSA Privacy training.
B.3. Role Based training is required for contract employees with Significant Security Responsibility (SSR), whose job proficiency is required for overall network security within TSA, and shall be in accordance with DHS and TSA policy. The contractor will be notified if they have a position with significant security responsibility.
B.4. Individuals with SSR shall have a documented individual training and education plan, which shall ensure currency with position skills requirements, with the first course to be accomplished within 90 days of employment or change of position. The individual training plan shall be refreshed annually or immediately after a change in the individual’s position description requirements.
B.5. Information Secuirty and Privacy training supplied by the Contractor shall meet standards established by NIST and set forth in DHS and TSA security policy.
B.6. The Contractor shall maintain a list of all employees who have completed training and shall submit this list to the contracting officer representative (COR) upon request, or during DHS/TSA onsite validation visits performed on a periodic basis.
B.7. The contractor shall its employees review and sign the TSA Form 1403 Computer and Wireless Mobile Device Access Agreement (CAA) prior to accessing IT systems.
C. Configuration Management (hardware/software)
C.1. Hardware or software configuration changes shall be in accordance with the DHS Information Security Performance Plan (current year and any updates thereafter), the DHS Continuous Diagnostics and Mitigation (CDM) Program to include dashboard reporting requirements and TSA’s Configuration Management policy. The TSA Chief Information Security Officer (CISO)/Information Assurance and Cyber Security Division (IAD) shall be informed of and involved in all configuration changes to the TSA IT environment including systems, software, infrastructure architecture, infrastructure assets, and end user assets. The TSA IAD POC shall approve any request for change prior to any development activity occurring for that change and shall define the security requirements for the requested change. The COR will provide access to the DHS Information Security Performance Plan.
C.2. The Contractor shall ensure all application or configuration patches and/or Requests for Change (RFC) have approval by the Technical Discussion Forum (TDF), Systems Configuration Control Board (SCCB) and lab regression testing prior to controlled change release under the security policy document, TSA Management Directive (MD) 1400.3 Information Technology Security and TSA Information Assurance (IA) Handbook, unless immediate risk requires immediate intervention. Approval for immediate intervention (emergency change) requires approval of the TSA CISO, SCCB co-chairs, and the appropriate Operations Manager, at a minimum.
C.3. The Contractor shall ensure all sites impacted by patching are compliant within 14 days of change approval and release.
C.4. The acquisition of commercial-off-the-shelf (COTS) Information Assurance (IA) and IA-enabled IT products (to be used on systems entering, processing, storing, displaying, or transmitting “sensitive information”) shall be limited to those products that have been evaluated and validated, as appropriate, in accordance with the following:
• The NIST FIPS validation program.
• The National Security Agency (NSA)/NIST, National Information Assurance Partnership (NIAP) Evaluation and Validation Program.
• The International Common Criteria for Information Security Technology Evaluation Mutual Recognition Agreement.
C.5. US Government Configuration Baseline and DHS Configuration Guidance
a) The provider of information technology shall certify applications are fully functional and operate correctly as intended on systems using the US Government Configuration Baseline (USGCB) and in accordance with DHS and TSA guidance.
1. USGCB Guidelines:
a. http://usgcb.nist.gov/usgcb_content.html
2. DHS Sensitive Systems Configuration Guidance
a. http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx
b) The standard installation, operation, maintenance, updates and/or patching of software shall not alter the configuration settings from the approved USGCB configuration. The information technology shall also use the Windows Installer Service for installation to the default “program files” directory and shall be able to discretely install and uninstall.
c) Applications designed for general end users shall run in the general user context without elevated system administration privileges.
C.6. The Contractor shall establish processes and procedures for continuous monitoring of Contractor systems that contain TSA data/information by ensuring all such devices are monitored by, and report to, the TSA Security Operations Center (SOC). The Contractor shall perform monthly security scans on servers that contain TSA data, and shall send monthly scan results to the TSA IAD.
D. Risk Management Framework
D.1. The Security Authorization and Ongoing Authorization Process in accordance with NIST SP 800- 37 and SP 800-137 (current versions) is a requirement for all TSA IT systems, including General Support Systems (e.g., standard TSA desktop, general network infrastructure, electronic mail), major applications and development systems (if connected to the operational network or processing, storing, or transmitting government data). These processes are documented in the NIST Risk Management Framework (RMF).
Ongoing Authorization is part of Step 6 “Monitoring” of the RMF. All NIST guidance is publicly available; TSA and DHS security policy is disclosed upon contract award with some exceptions, which are public facing (i.e., DHS Security and Training Requirements for Contractors).
D.2. A written Authorization to Operate (ATO) granted by the TSA Authorizing Official (AO) also known as TSA Chief Information Secuirty Officer (CISO) is required prior to processing operational data or connecting to any TSA network. The contractor shall provide all necessary system information for the security authorization effort.
http://usgcb.nist.gov/usgcb_content.html http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx https://www.dhs.gov/dhs-security-and-training-requirements-contractors
D.3. TSA shall assign a security category to each IT system compliant with the requirements of Federal Information Processing Standards (FIPS) Pub 199 Standards for Security Categorization of Federal Information and Information Systems impact levels and assign security controls to those systems consistent with FIPS Pub 200 Minimum Security Requirements for Federal Information and Information Systems methodology.
D.4. Unless the AO specifically states otherwise for an individual system, the duration of any Accreditation shall be dependent on the FIPS 199 rating and overall residual risk of the system; the length can span up to 36 months.
D.5. The Security Authorization (SA)Package contains documentation required for Security Authorizations and Ongoing Authorization. The package shall contain the following security documentation: 1) Security Assessment Report (SAR), 2) Security Plan (SP) or System Security Authorization Agreement (SSAA), 3) Contingency Plan, 4) Contingency Plan Test Results, 5) Federal Information Processing Standards (FIPS) 199 Security Categorization, 6) Privacy Threshold Analysis (PTA), 7) E-Authentication, 8) Security Assessment Plan (SAP), 9) Authorization to Operate (ATO) Letter, 10) Plan of Action and Milestones (POA&M), and 11) Ongoing Authorization Artifacts as required by the DHS Ongoing Authorization Methodology (current version). The SA package shall document the specific procedures, training, and accountability measures in place for systems that process personally identifiable information (PII). All security compliance documents shall be reviewed and approved by the CISO and the IAD, and accepted by the CO upon creation and after any subsequent changes, before they go into effect. Ongoing Authorization artifacts include monthly TRigger Accountability Log (TRAL), monthly operating system scan results, application scans as directed, updated control allocation table (CAT), and associated memos as directed. All steps in the DHS Information Assurance Compliance Systems (IACS) shall be completed correctly, thoroughly and in a timely manner for all steps of the RMF.
D.6. The contractor shall support the successful remediation of all identified system weaknesses and vulnerabilities that are identified as a result of the aforementioned security review process.
D.7. The contractor shall submit and analyze monthly operating system vulnerability scans for the DHS Information Security Performance Plan FISMA Scorecard. Vulnerabilities not remediated are generated into Plan of Action and Milestone (POA&M)s after 30 days.
E. Contingency Planning
E.1. The Contractor shall develop and maintain a Contingency Plan (CP), to include a Continuity of Operation Plan (COOP), to address circumstances whereby normal operations may be disrupted and thus require activation of the CP and/or COOP. are disrupted. The contractor’s CP/COOP responsibility relates only to the system they provide or operate under contract.
E.2. The Contractor shall ensure that contingency plans are consistent with template provided in the DHS IACS Tool. If access has not been provided initially, the contractor shall use the DHS 4300A Sensitive System Handbook, Attachment K IT Contingency Plan Template.
E.3. The Contractor shall identify and train all TSA personnel involved with COOP efforts in the procedures and logistics of the disaster recovery and business continuity plans.
E.4. The Contractor shall ensure the availability of critical resources and facilitate the COOP in an emergency situation.
E.5. The Contractor shall test their CP annually and retain records of the annual CP testing for review during periodic audits.
E.6. The Contractor shall record, track, and correct any CP deficiency; any deficiency correction that cannot be accomplished within one month of the annual test shall be elevated to IAD.
E.7. The Contractor shall ensure the CP addresses emergency response, backup operations, and recovery operations.
E.8. The Contractor shall have an Emergency Response Plan that includes procedures appropriate to fire, flood, civil disorder, disaster, bomb threat, or any other incident or activity that may endanger lives, property, or the capability to perform essential functions.
E.9. The Contractor shall have a Backup Operations Plan that includes procedures and responsibilities to ensure that essential operations can be continued if normal processing or data communications are interrupted for any reason.
E.10. The Contractor shall have a Post-disaster Recovery Plan that includes procedures and responsibilities to facilitate rapid restoration of normal operations at the primary site or, if necessary, at a new facility following the destruction, major damage, or other major interruption at the primary site.
E.11. The Contractor shall ensure all TSA data (e.g., mail, data servers, etc.) is incrementally backed up on a daily basis.
E.12. The Contractor shall ensure a full backup of all network data occurs as required by the system’s availability security categorization impact rating per TSA Information Assurance policy.
E.13. The Contractor shall ensure all network application assets (e.g., application servers, domain controllers, Information Assurance (IA) tools, etc.) shall be incrementally backed up as required to eliminate loss of critical audit data and allow for restoration and resumption of normal operations within one hour.
E.14. The Contractor shall ensure sufficient backup data to facilitate a full operational recovery within one business day at either the prime operational site or the designated alternate site shall be stored at a secondary location determined by the local element disaster recovery plan.
E.15. The Contractor shall ensure that data at the secondary location is current as required by the system’s availability security categorization impact rating.
E.16. The Contractor shall ensure the location of the local backup repository and the secondary backup repository is clearly defined, and access controlled as an Information Security Restricted Area (ISRA).
E.17. The Contractor shall adhere to the DHS IT Security Architecture Guidance Volume 1: Network and System Infrastructure for the layout of the file systems, or partitions, on a system’s hard disk impacting the security of the data on the resultant system. File system design shall:
• Separate generalized data from operating system (OS) files
• Compartmentalize differing data types
• Restrict dynamic, growing log files or audit trails from crowding other data
E.18. The contractor shall adhere to the DHS IT Security Architecture Guidance Volume 1: Network and System Infrastructure for the management of mixed data for OS files, user accounts, externally-accesses data files and audit logs.
F. Program Performance
F.1. The Contractor shall comply with requests to be audited and provide responses within three business days to requests for data, information, and analysis from the TSA IAD and management, as directed by the Contracting Officer (CO).
F.2. The Contractor shall provide support during the IAD audit activities and efforts. These audit activities shall include, but are not limited to the following: requests for system access for penetration testing, vulnerability scanning, incident response and forensic review.
F.3. Upon completion of monthly security scans, findings shall be documented and categorized as High, Moderate, or Low based on their potential impact to the System IT Security posture. The Contractor shall provide TSA with estimates of the total engineering service hours required to support the remediation of open POA&M items. High security findings shall be remediated first in 45 days or less;
Moderate security findings shall be remediated in 60 days or less, and Low security findings shall be remediated in 90 days or less. The Contractor shall work with the TSA System ISSO and the respective CO and/or Contracting Officer’s Representative (COR), as well as OIT IAD and the System Owner (as required) to prioritize and plan for the remediation of open POA&Ms. The TSA System ISSO shall maintain all security artifacts and perform Ongoing Authorization (per NIST 800-137 and DHS-TSA requirements) and Continuous Diagnostics and Mitigation (CDM) (per OMB M-14-03) activities to ensure active compliance with security requirements. Specific POA&M guidance and information can be found in the SOP 1401 Plan of Action and Milestone (POA&M) Process, as well as the DHS 4300A PD Attachment H Plan of Action and Milestones (POA&M) Process Guide.
G. Federal Risk and Authorization Management Program (FedRAMP)
If a vendor is to host a system with a Cloud Service Provider, the following shall apply:
G.1. FedRAMP Requirements: Private sector solutions shall be hosted by a Joint Authorization Board (JAB)-approved Infrastructure as a Service (IaaS) Cloud Service Provider (CSP) (http://cloud.cio.gov/fedramp/cloud-systems) and shall follow the Federal Risk and Authorization Management Program (FedRAMP) requirements. The CSP shall adhere to the following in addition to the FedRAMP requirements:
• Identity and entitlement access management shall be done through Federated Identity;
• SSI and PII shall be encrypted in storage and in transit as it is dispersed across the cloud;
• Sanitization of all TSA data shall be done as necessary at the IaaS, PaaS or SaaS levels;
• Cloud bursting shall not occur;
http://cloud.cio.gov/fedramp/cloud-systems
• TSA data shall be logically separated from other cloud tenants;
• All system administrators shall be properly cleared and vetted U.S. citizens;
• TSA data shall not leave the United States; and
• The cloud internet connection shall be behind a commercial Trusted Internet Connection (TIC) that has EINSTEIN 3 Accelerated (E3A) capabilities deployed. These include but are not limited to the analysis of network flow records, detecting and alerting to known or suspected cyber threats, intrusion prevention capabilities and under the direction of DHS detecting and blocking known or suspected cyber threats using indicators. The E3A capability shall use the Domain Name Server Sinkholing capability and email filtering capability allowing scans to occur destined for .gov networks for malicious attachments, Uniform Resource Locators and other forms of malware before being delivered to .gov end-users.
G.2. Private Sector System Requirements: TSA shall conduct audits at any time on private sector systems, and the system shall be entered into the TSA FISMA Inventory as a system of record using the Control Implementation Summary (CIS) provided by the Cloud Service Provider. Security artifacts shall be created and maintained in the DHS IACS. The private sector systems are required to go through the Security Authorization Process and the RMF in accordance the Federal Information Systems Management Act (FISMA) and NIST SP 800-37 Rev. 1. The cloud internet connection shall be behind a commercial Trusted Internet Connection (TIC) that has E3A deployed. Security event logs and application logs shall be sent to the TSA SOC. Incidents as defined in the TSA Management Directive 1400.3 and its Attachment 1 (TSA IA Handbook) shall be reported to the TSA SPOC 1-800-253-8571. DHS Information Security Vulnerability Management Alerts and Bulletins shall be patched within the required time frames as dictated by DHS and communicated by the contracting officer representative (COR) or contract security point of contact (POC).
H. Information Assurance Policy
H.1. All services, hardware and/or software provided under this task order shall be compliant with applicable DHS 4300A Sensitive System Policy Directive, DHS 4300A Sensitive Systems Handbook, TSA MD 1400.3 Information Technology Security, TSA IA Handbook, Technical Standards (TSs) and standard operating procedures (SOPs).
H.2. The contractor solution shall follow all current versions of TSA and DHS policies, procedures, guidelines, and standards, which shall be provided by the Contracting Officer.
H.3. Authorized access and use of TSA IT systems and resources shall be in accordance with the TSA IA Handbook.
H.4. The contractor shall complete TSA Form 251 and TSA Form 251-1 for sensitive or accountable property. The contractor shall email the completed forms to TSA-Property@dhs.gov and include a hard copy with the shipment.
I. Data Stored/Processed at Contractor Site mailto:TSA-Property@dhs.gov
I.1. Unless otherwise directed by TSA, any storage of data shall be contained within the resources allocated by the Contractor to support TSA and may not be on systems that are shared with other commercial or government clients.
J. Remote Access
J.1. The Contractor remote access connection to TSA networks shall be considered a privileged arrangement for both Contractor and the Government to conduct sanctioned TSA business. Therefore, remote access rights shall be expressly granted, in writing, by the TSA IAD.
J.2. The Contractor employee(s) remote access connection to TSA networks shall be terminated immediately for unauthorized use, at the sole discretion of TSA.
J.3. The Contractor shall use his or her federal issued…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .